US12388856B2ActiveUtilityA1

Detection, validation, and sourcing of malicious AI-generated distributed data

Assignee: BANK OF AMERICAPriority: Aug 21, 2023Filed: Aug 21, 2023Granted: Aug 12, 2025
Est. expiryAug 21, 2043(~17.1 yrs left)· nominal 20-yr term from priority
G06Q 50/205G06N 5/022G06F 3/04842H04L 63/1416H04L 41/16H04L 63/1425
58
PatentIndex Score
0
Cited by
15
References
20
Claims

Abstract

An information security method to detect, validate, source, and/or remediate propagated, maliciously generated, AI content is disclosed. Search-engine spider(s) to crawl the Internet to identify posted content, which is analyzed with signature-based detection, anomaly detection, and machine learning to identify suspect content, which is compared against validated content. A malicious-AI probability score is generated based on the results of the foregoing AI analysis and the content differences. Metadata corresponding to the suspect content is extracted. A malicious activity mapping is compiled from available data. Suspect content is attempted to be recreated by publicly available online AI bots to identify the AI engine that generated the malicious content. Metadata pertaining to the origination source that accessed the source AI bot. Metadata is used to trace the malicious content back to the originator. Proofs regarding the foregoing are generated. Notifications/demands may be generated. Countermeasures against future attacks may be deployed.

Claims

exact text as granted — not AI-modified
The invention claimed is: 
     
       1. An information-security process for detection, validation, and sourcing of malicious AI-generated content distributed on the Internet comprising the steps of:
 deploying, by an artificial intelligence (AI) engine, a search-engine spider to crawl the Internet to identify posted content propagated across online sources; 
 analyzing, by the AI engine, the posted content using signature-based detection, anomaly detection, and machine learning to determine whether the posted content is suspect content that was potentially maliciously generated; 
 comparing, by the AI engine, validated content against the suspect content in order to identify an extent of content differences; 
 generating, by the AI engine, a malicious-AI probability score based on the signature-based detection, anomaly detection, and the machine learning, as well as the extent of the content differences, and, if the malicious-AI probability score exceeds a malicious-AI confidence threshold: 
 extracting, by the AI engine from the online sources, first metadata corresponding to the suspect content; 
 compiling, by the AI engine, a malicious activity mapping; 
 recreating, by the AI engine using online AI bots that are publicly accessible, the first metadata, and the malicious activity mapping, the suspect content in order to identify a source AI bot that was maliciously utilized based on which of the online AI bots are able to successfully recreate the suspect content; 
 extracting, by the AI engine from the source AI bot, second metadata corresponding to an original creation of the suspect content; 
 tracing, by the AI engine based on the second metadata, the suspect content back to an origination source; 
 generating, by the AI engine, proof that the suspect content is false and that the source AI bot was maliciously used to create the suspect content; and 
 issuing, by the AI engine, at least one notification regarding the suspect content, the origination source, the source AI bot, and the proof. 
 
     
     
       2. The information-security process of  claim 1  wherein the machine learning performs pattern recognition that is utilized by the AI engine in order to generate malicious-AI probability score. 
     
     
       3. The information-security process of  claim 2  further comprising the step of performing, by the AI engine based on the malicious activity mapping and the first metadata, a trend analysis to determine whether negative activity as a result of the suspect content is trending increasingly negative based on time. 
     
     
       4. The information-security process of  claim 3  wherein the malicious-AI probability score is further based on comparison to historical data relating to previously detected malicious campaigns. 
     
     
       5. The information-security process of  claim 4  wherein the first metadata includes: a post time, a post date, a posting IP address, posting user indicia, and post keywords. 
     
     
       6. The information-security process of  claim 5  wherein the suspect content includes at least one false image and the validated data stores include valid images. 
     
     
       7. The information-security process of  claim 6  wherein the online sites are social media sites or news outlets. 
     
     
       8. The information-security process of  claim 7  further comprising detecting, by the AI engine, other posts corresponding to the posting user indicia in order to help identify the origination source for the suspect content. 
     
     
       9. The information-security process of  claim 8  wherein the steps are automated and executed in real time. 
     
     
       10. The information-security process of  claim 9  further comprising the step of implementing, by the AI engine, first countermeasures to prevent further access to the source AI bot from the origination source. 
     
     
       11. The information-security process of  claim 10  wherein said at least one notification includes an automated takedown demand transmitted to at least one of the online sources. 
     
     
       12. The information-security process of  claim 11  further comprising the step of implementing, by the AI engine, second countermeasures to preempt access by the origination source to at least one of the online AI bots. 
     
     
       13. The information-security process of  claim 12  wherein the malicious activity mapping includes frequency timing data identifying post timing intervals for propagation of the suspect content. 
     
     
       14. An automated, real-time, information-security process for detection, validation, sourcing, and remediation of malicious AI-generated content distributed on the Internet comprising the steps of:
 deploying, by an artificial intelligence (AI) engine, a plurality of search-engine spiders to crawl the Internet in parallel to identify posted content propagated across online sources; 
 analyzing, by the AI engine, the posted content using signature-based detection, anomaly detection, and machine-learning pattern recognition to generate threat-assessment results indicating whether the posted content is suspect content that was potentially maliciously generated; 
 comparing, by the AI engine, validated content in validated data stores against the suspect content in order to identify an extent of content differences; 
 generating, by the AI engine, a malicious-AI probability score based on threat-assessment results, the extent of the content differences, and historical data relating to previously detected malicious campaigns, and, if the malicious-AI probability score exceeds a malicious-AI confidence threshold: 
 extracting, by the AI engine from the online sources, first metadata corresponding to the suspect content, said first metadata including: a post time, a post date, a posting IP address, posting user indicia, and post keywords; 
 detecting, by the AI engine, other posts corresponding to the posting user indicia in order to facilitate identification of the origination source for the suspect content; 
 compiling, by the AI engine based on the first metadata, the suspect content the threat-assessment results, and the other posts, a malicious activity mapping that includes frequency timing data identifying post timing intervals for propagation of the suspect content; 
 recreating, by the AI engine using online AI bots that are publicly accessible, the first metadata, and the malicious activity mapping, the suspect content in order to identify a source AI bot that was maliciously utilized based on which of the online AI bots are able to successfully recreate the suspect content; 
 extracting, by the AI engine from the source AI bot, second metadata corresponding to an original creation of the suspect content; 
 tracing, by the AI engine based on the second metadata, the suspect content back to an origination source; 
 generating, by the AI engine, proof that the suspect content is false and that the source AI bot was maliciously used to create the suspect content; 
 performing, by the AI engine based on the malicious activity mapping and the first metadata, a trend analysis to determine whether negative activity as a result of the suspect content is trending increasingly negative based on time; 
 issuing, by the AI engine, at least one takedown demand to the online sources that includes the suspect content, the origination source, the source AI bot, and the proof; and 
 deploying, by the AI engine, countermeasures to attempt to prevent future access by the origination source to the online AI bots. 
 
     
     
       15. The information-security process of  claim 14  wherein the online sources are social media sites. 
     
     
       16. The information-security process of  claim 14  wherein the online sources are news outlets. 
     
     
       17. The information-security process of  claim 15  wherein the suspect content includes at least one false image and at least one false video and the validated data stores include at least one valid image and at least one valid video. 
     
     
       18. An automated, real-time, information-security process for detection, validation, sourcing, and remediation of malicious AI-generated content distributed on the Internet comprising the steps of:
 deploying, by an artificial intelligence (AI) engine, a plurality of masked search-engine spiders to surreptitiously crawl the Internet in parallel to identify posted content propagated across social-media online sources; 
 analyzing, by the AI engine, the posted content using signature-based detection, anomaly detection, and machine-learning pattern recognition to generate threat-assessment results indicating whether the posted content is suspect content that was potentially maliciously generated; 
 comparing, by the AI engine, validated content in validated data stores against the suspect content in order to identify an extent of content differences; 
 generating, by the AI engine, a malicious-AI probability score based on threat-assessment results, the extent of the content differences, and historical data relating to previously detected malicious campaigns, and, if the malicious-AI probability score exceeds a malicious-AI confidence threshold: 
 surreptitiously extracting, by the AI engine from the social-media online sources, first metadata corresponding to the suspect content, said first metadata including: a post time, a post date, a posting IP address, posting user indicia, and post keywords; 
 surreptitiously detecting, by the AI engine, other posts corresponding to the posting user indicia in order to facilitate identification of the origination source for the suspect content; 
 compiling, by the AI engine based on the first metadata, the suspect content the threat-assessment results, and the other posts, a malicious activity mapping that includes frequency timing data identifying post timing intervals for propagation of the suspect content; 
 surreptitiously recreating, by the AI engine using online AI bots that are publicly accessible, the first metadata, and the malicious activity mapping, the suspect content in order to identify a source AI bot that was maliciously utilized based on which of the online AI bots are able to successfully recreate the suspect content; 
 surreptitiously extracting, by the AI engine from the source AI bot, second metadata corresponding to an original creation of the suspect content; 
 tracing, by the AI engine based on the second metadata, the suspect content back to an origination source; 
 generating, by the AI engine, proof that the suspect content is false and that the source AI bot was maliciously used to create the suspect content; 
 performing, by the AI engine based on the malicious activity mapping and the first metadata, a trend analysis to determine whether negative activity as a result of the suspect content is trending increasingly negative based on time; 
 issuing, by the AI engine, at least one takedown demand to the social-media online sources that includes the suspect content, the origination source, the source AI bot, and the proof; and 
 deploying, by the AI engine, countermeasures to attempt to prevent future access by the origination source to the online AI bots. 
 
     
     
       19. The information-security process of  claim 18  wherein the suspect content includes at least one false image and the validated data stores include at least one valid image. 
     
     
       20. The information-security process of  claim 19  wherein the suspect content includes at least one false video and the validated data stores include at least one valid video.

Join the waitlist — get patent alerts

Track US12388856B2 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.